Attribute-Based Access Control — define fine-grained admin permissions
Full platform access for super administrators
Security admins can manage policies and profiles but not system settings
Network admins can manage gateways and tunnel configurations
Auditors have read-only access to logs, policies, and reports
Deny admin actions from non-corporate IPs without MFA